Cisco today released security updates to address two high-severity vulnerabilities identified in the Cisco Webex Meetings Desktop app for Windows and macOS that could allow hackers to execute programs and code on vulnerable devices.

Cisco Webex Meetings is an online meeting and video conferencing software that makes it easy to schedule and join meetings. The platform also provides presentation, screen sharing, and recording capabilities.
The two vulnerabilities are listed as CVE-2020-3263 and CVE-2020-3342 and affect versions earlier than 39.5.12 of the Cisco Webex Meetings Desktop App and versions earlier than 39.5.11 of the Cisco Webex Meetings Desktop App for Mac.
Run remote programs on Windows systems
The arbitrary program execution security flaw affecting the Windows client is caused by improper input validation of URLs provided in versions of the Cisco Webex Meetings Desktop App.
CVE-2020-3263 could allow unauthenticated remote attackers to execute arbitrary code on systems running an unpatched version of the application . An attacker could exploit this vulnerability by tricking a target into clicking a malicious URL.
"A successful exploit could allow the attacker to cause the application to execute other programs already on the system," Cisco says.
“If malicious files are present on the system, an attacker could execute arbitrary code on the affected system.”
Remotely execute arbitrary code on a Mac
The remote code execution vulnerability found in the macOS client is due to improper certificate validation in software update files downloaded from affected versions of Cisco Webex Meetings Desktop App for Mac.
CVE-2020-3342 could allow unauthenticated attackers to remotely execute arbitrary code with the privileges of the user logged in to the Mac running unupdated versions of the Cisco Webex Meetings Desktop app.
"An attacker could exploit this vulnerability by convincing a user to go to a website that 'displays' files on the client that are similar to files 'displayed' on the legitimate Webex website," Cisco explains.
“The customer may fail to properly validate the cryptographic protection methods of the provided files before executing them as part of an update.”.
Solution
While there are no known workarounds that address these two vulnerabilities, Cisco has released free software updates to fix the flaws.
Cisco's Product Security Incident Response Team (PSIRT) has not yet identified any malicious use of these vulnerabilities.
Cisco has fixed CVE-2020-3263 in Cisco Webex Meetings Desktop App version 40.1.0 and later.
CVE-2020-3342 was fixed in Cisco Webex Meetings Desktop App for Mac versions 39.5.11 and later.
Windows and macOS users can update the Cisco Webex Meetings Desktop App using the instructions in the Cisco Webex Meetings Desktop App Help Center article
Administrators can update the two applications for their entire user base by following the detailed instructions available in this guide from Webex.
